cURL / Mailing Lists / curl-library / Single Mail

curl-library

weak cipher suites with OpenSSL, SecureTransport and... ?

From: Daniel Stenberg <daniel_at_haxx.se>
Date: Thu, 9 Jan 2014 23:34:19 +0100 (CET)

Howdy,

Here are two fresh (and annoying) issues we need to fix:

#1323 - remove export cipher suites from OpenSSL preference list
  https://sourceforge.net/p/curl/bugs/1323/

#1324 - curl built with SecureTransport includes support for NULL ciphersuites
         in ClientHello
  https://sourceforge.net/p/curl/bugs/1324/

Left to do is then to build curl with other TLS backends and try it against
https://www.howsmyssl.com/a/check to see if there are more flaws in this
style.

-- 
  / daniel.haxx.se
-------------------------------------------------------------------
List admin: http://cool.haxx.se/list/listinfo/curl-library
Etiquette:  http://curl.haxx.se/mail/etiquette.html
Received on 2014-01-09